19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code
- ID
- 19097
- Status
- summarized
- Published
- 28 Aug 2026, 11:27 PM
- Fetched
- 28 Aug 2026, 11:42 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/08/19-chrome-and-edge-extensions-found.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 5.5
- Created
- 28 Aug 2026, 11:44 PM
- Tags
- Audience
- developersvibe_codersSaaS/startup_founders
What happened
Socket researcher Karlo Zanki identified 19 Chrome and Edge extensions (14 newly created, 5 purchased from prior owners) that were pushed as clean versions and later updated with wallet-stealing and crypto-draining code, in a campaign tracked as 'Superior' and active since February 2024. The tactic involves either buying legitimate extensions or shipping a benign version first, then publishing a malicious update once user downloads accumulate.
Why it matters
If your team installs browser extensions for SEO, crypto, PDF tools, or screen-capture utilities, audit the listed extension IDs against your managed browser policies—five of these were previously legitimate extensions bought out and turned malicious, so reputation and download counts are not reliable trust signals. Founders shipping browser extensions should treat the update pipeline as an attack surface and consider code-signing or integrity checks for their own published extensions.
Discussion angle
The 'buy a legitimate extension and push a malicious update' playbook means extension store ratings and install counts are adversarially manipulable—discuss what verification, if any, is practical before allowing a new extension into a developer's browser.